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Summary 


The purpose of this guide is to provide a detailed overview of how to enable Qualys Context 
Extended Detection and Response (XDR). Qualys splits the enabling process over several phases. 
This guide covers the activities on Day 0, during which an appliance is deployed, and a collector 
is set up. This also covers information to set up the Qualys Windows Cloud Agent for XDR. 


A Day 4 - Incident Mgmt 
A Day 3 - Detection Model A Signal Dashboard 


+ Signal Investigation 


+ Context Enrichment 


AÁ DA |. Correlation Rules 
E + Behavior Rules 
A SA |. Log Analytics Dashboard 
+ Log Enrichment 
Day 0 - Deployment - 3 party Log Collection 


+ SIEM Data Ingestion 


+ Special Object Setup 


+ Leverage Tags 


+ Search Queries 


+ Windows Log Collection 


+ Appliance Deployment 


+ Syslog Collector Setup 
- Windows Agent 


Day O - Deployment 


On Day 0, we will walk you through the steps to: 
1. Deploy an appliance 
2. Setupa collector 
3. Prepare Qualys Cloud Agent for XDR 
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Appliance Deployment 


Deploying an appliance involves 5 stages: 


Gi IOs 


Download the appliance image 
Deploy and verify the appliance 
Generate the registration code 
Apply the registration code 
Verify the activation 


To know more information on the appliance size requirements, refer to the Appliance — Sizing 
calculations section in the Online Help. 


Stage 1: Download the Appliance Image 


Qualys appliance image is available for download right from the Qualys Context XDR UI. Follow 
these steps to download the image: 


1. 


From the module picker, select XDR to access the Extended Detection and Response (XDR) 
module within the Qualys Cloud Platform. 

On the Qualys Context XDR Ul, click Configuration. 

© Qualys. Cloud Platform 


DASHBOARD THREAT MANAGEMENT ADVANCED ANALYTICS RULES | CONFIGURATION 
— 


AMAIA overview 


Click the drop-down box near Configuration Overview. 


© Qualys. Cloud Platform 


XDR + DASHBOARD THREAT MANAGEMENT ADVANCED ANALYTICS RULES CONFIGURATION 


eee COMA Overview 


Configurations 


On the drop-down menu, select the option for Data Collection. 


© Qualys. cioud Platform 


XDR + DASHBOARD THREAT MANAGEMENT ADVANCED ANALYTICS RULES CONFIGURATION 


Overview 


ation Overview | 


Data Collection 


Response Templates 


Special Objects 
Threat Intel 


Cloud Agent Profiles 
User Lists E Response Templates @ Special Objects 


as a = u ai = ms 
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5. Next, click Appliances. 


© Qualys. Cloud Platform 


XDR + DASHBOARD THREAT MANAGEMENT ADVANCED ANALYTICS RULES CONFIGURATION 


Data Collection Sources Collectors Appliances 


Q Search 


6. On the Appliances tab, click the Download Image button to view available links to download 
the image. You can use the downloaded image to create a VM. 


© Qualys. Cloud Platform 
XDR + DASHBOARD THREAT MANAGEMENT ADVANCED ANALYTICS RULES CONFIGURATION 
Data Collection A TA CATE Appliances 
Q Search... 


Stage 2: Deploy and Verify the Appliance 


It is imperative to deploy the appliance within your environment such that there is network 
connectivity between the log sources and the appliance and between the appliance and the 
Qualys Cloud platform. See Appendix A for a few network diagrams on the recommended 
appliance deployment. 


Note: If needed, consult your Solutions Architect for assistance. 
Follow these steps to deploy the appliance: 


1. Deploy the image you downloaded. After deploying, the appliance may need 5-10 minutes to 
boot up the first time. After the appliance fully boots, console into the virtual machine to 
view this screen: _ 


Register the Appliance with Qualys} 
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2. By default, the appliance tries to automatically configure via DHCP. To verify the IP address, 
select Info to view the following screen: 


etha : 18.114.252. 189/24 

QAG Status : Not Connected 

QAG Status URL : https://qagpublic.p23.eng.in83.qualys.com/status 
DNS Servers : 18.114.25.21 

System Time : 12/15/21 05:53:89 

System Timezone : UTC 

Appliance ID : 3810b314-5d14-488a-958b-73115448d443 


Appliance Name : AMITU_18.114.252.188 

Qualys URL : https://camspublic.p23.eng. in83.qualys. com 
System Updates : Up to date 

Bui ld-version : 1.1.8-334 

Service Version : 


Note: XDR only supports a static IP address. If you need DHCP, contact Technical Account 
Manager (TAM). 


3. Toassign a static IP address, return to the main menu and Select System Settings. 


Configuration 


Registration Register the Appliance with Qualys 
S 

Info General Information 

Diagnostics Information 

Commands Various commands 


4. On the System Configuration menu, Select Network Settings. 
Qualys Inc. USE:<«tl> to navigate ENTER to confirm 


System Configuration 


etwork Settings 


System Time Settings 
Qualys URL Edit Qualys Services URL 
Disable SSH Disable SSH 


< Back > 
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5. On the Network Configuration menu, Select Network Interface Settings. 


If required, define specific DNS settings and proxy information. 
Qualys Inc. USE:<«tl> to navigate ENTER to confirm 


Configuration 


etwork Interface Settings (eth@ ) 
DNS Settings 


Proxy Server 


< Back > 


6. On the Network interface Configuration menu. Select Static. 
Qualys Inc. USE:¢tl> to navigate SPACE to select ENTER to confirm 


Network interface configuration 
€ ) DHCP 


EI 


Unconfigured 


<Cancel> 


Note: XDR only supports a static IP address. If you need DHCP, contact Technical Account 
Manager (TAM). 


7. Enter the IP address and Gateway to configure the interface that conforms to the virtual 


network/switch where the virtual machine image is deployed. 
Qualys Inc. USE:fî4 to navigate TAB to focus ENTER to confirm 


IP (CIDR): MERA 
Gateway: 18.114.252.1 


< OR > < Back > 
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8. Once the network is successfully configured, return to the main menu and see if the 
Registered status is shown as Appliance is registered with Qualys. 


Qualys Inc. USE:+«tJ> to navigate ITER to confirm 


Appliance is Registered with Qualys 


9. Also, if the network is successfully configured, QAG Status should show as Connected on the 
Info screen under the General information of main menu. 


Qualys Inc. 


The initial stages of the appliance setup are considered as verified when the QAG Status is 
Connected. You can now proceed to generate an activation code from the XDR UI. 
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Stage 3: Generate Activation Code 


After you have deployed an appliance, you need to bind it with the Qualys Cloud Platform. 
Qualys uses an activation code for this purpose. 


Follow these steps to generate an activation code: 


1. On the Qualys Cloud Platform, under XDR > Configuration > Data Collection > 
Appliance, click New Appliance. 


© Qualys. Cloud Platform 
XDR + DASHBOARD THREAT MANAGEMENT ADVANCED ANALYTICS 
Data Collection TT EEN Appliances 
CE Search 


RULES 


CONFIGURATION 


2. Enter the Appliance Name, Description, and Location details you want to use for the 
appliance and click Save. 


< New Appliance 


Appliance registration 
Create new appliance 


Appliance Name * 


NewAppliance 


Description 


Based out of HQ 


Location 


California 


Personalization code will be generated after successful save and will be visibl 
View Details. Please use the code to register the appliance. 


| concer] pms 


1009/1024 characters re 
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3. An Appliance registration code is generated when the appliance is saved. This registration 
code is required in the Apply Activation Code section. 


Appliance registration code 


Make a note of the activation code. This is required for appliance registration to Qualys cloud. You can view the 
code in appliance details section as well. 


Sample view of appliance registration screen 


The appliance is visible on the Appliances tab with the Unregistered status. 


Stage 4: Apply Activation Code 


To bind the virtual machine appliance deployed in the Deploy and Verify the 
Application section with the Qualys Cloud Platform, you need to register the appliance with the 
registration code generated in stage 3. 


Follow these steps to register your appliance: 


1. Access the appliance deployed and verified in the Deploy and Verify the Application section 
via the console. 


Le On ie Core nea 


Register the Appliance with Qualys] 
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3. Next, enter the registration code generated in the Generate Registration Code section and 
select OK. 


TIP: Some consoles do not allow copy-paste. You might have to manually type in the 
registration code on such consoles. 


Stage 5: Verify Activation 


The final step in deploying an appliance is verifying the deployment. To verify the deployment, 
on the Qualys Ul, navigate to Configuration > Data Collection > Appliance. The appliance you 
deployed should be displayed with the status as Active. 


Data Collection {v 


Catalog Sources AUTO Appliances 


Download Image 1-150f 15 


STATUS FRIENDLY NAME CREATED ON DEPLOYMENT LOCATION — VERSION IP ADDRESS 


Active RAI Jul 7,2021 03:11 pm EU - 10.114.252.16 = 
a minute ago B 


If the status does not update or continues to show ‘Unregistered’ after 10 minutes, contact your 
Solutions Architect for assistance. 
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Collector Deployment 


After the new application is deployed, you can deploy and prepare log collectors for ingestion to 
the Qualys Context XDR Platform. Depending on your initial scope, you can deploy a syslog 
collector and/or perform Windows Agent activation (WLC logging profile will be on Day 1). 


IMPORTANT: To continue, validate your XDR appliance is successfully registered and the status 
appears as Active. 


You can deploy the following collectors: 


e Syslog Collector 
e Active Directory Collector 


Syslog Collector 


Follow these steps to configure a Syslog collector: 


1. 


3, 


From the Qualys Context XDR UI, click Configuration. 
© Qualys. Cloud Platform 


XDR + DASHBOARD THREAT MANAGEMENT ADVANCED ANALYTICS RULES CONFIGURATION 


(AMAIA Overview 


Configurations 


From the Configuration Overview menu, select Data Collection. 


O Qualys. cioud Platform 


XDR + DASHBOARD THREAT MANAGEMENT ADVANCED ANALYTICS RULES CONFIGURATION 


Overview 


A nin An 


Data Collection 


Response Templates 


Special Objects 

Threat Intel 

Cloud Agent Profiles 

User Lists E Response Templates i) Special Objects 


zmer; au as = s Pa = == 


From the secondary navigation bar, select Collectors. 


© Qualys. Cloud Platform 


XDR + DASHBOARD THREAT MANAGEMENT ADVANCED ANALYTICS RULES CONFIGURATION 


Data Collection Catalog MOMATSI AN ETT 
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4. Next, click the New collector button. 


O Qualys. cloud Platform 


XDR + DASHBOARD THREAT MANAGEMENT ADVANCED ANALYTICS RULES CONFIGURATION 


Data Collection z Catalog AT Collectors Appliances 


19 


Total Collectors 


5. Enter a Name and Description for the collector. 
In our example, we chose a naming convention that will quickly give us the information. 


Collector Details 


Name * 


USL-SYSLOG 


Description * 


This is a syslog collector 


Za 
998/1024 characters remaining 


Type * 

Select type of collector v 
Appliance + 

Select appliance v 


HeartBeat Interval * 


Select HeartBeat interval in minutes v 


Cancel Save 


6. Next, from the Type dropdown list, choose Syslog. 
7. The Appliance drop-down lists all the active appliances you have already deployed. Select 
the appliance you want to deploy this Syslog collector on. 
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8. When you set the Type to SYSLOG, additional details will open up. Define the protocol and 
port number you want the collector to listen on and then click Save. 


Collector Configuration 


Port * 


514 


Protocol * 


UDP 


9. After a few minutes, when the collector binds successfully, the collector status appears as 
Active under the Collectors tab. 


Catalog Sources Collectors Appliances 


Q 


STATUS COLLECTOR NAME TYPE LAST COLLECTION NEXT COLLECTION 


Active SYSLOG_10.114.252.173 SYSLOG Not applicable Not applicable 
4 minutes ago SYSLOG_10.114.252.173 


If the status does not show Active, try the following: 
e Recheck the parameters and verify the credentials. 
e Attempt configuring the collector on a different port. 


If the status does not change to Active, contact your Qualys Technical Account Manager (TAM) 
or Solution Architect. You can also contact Qualys Support to resolve your issue. 
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Active Directory Collector 


An Active Directory collector allows you to import your organization's user directory and user 
attributes into Qualys Context XDR. XDR uses this user data to enrich data from other log 
sources. 


Follow these steps to configure an Active Directory collector: 


1. From the Qualys Context XDR UI, click Configuration. 
© Qualys. Cloud Platform 


XDR + DASHBOARD THREAT MANAGEMENT ADVANCED ANALYTICS RULES CONFIGURATION 


AMAIA Overview 


Configurations 


2. From the Configuration Overview menu, select Data Collection. 


© Qualys. cioud Platform 


XDR + DASHBOARD THREAT MANAGEMENT ADVANCED ANALYTICS RULES CONFIGURATION 


Configuration Overview Overview 


Data Collection 


Response Templates 
Special Objects 
Threat Intel 


Cloud Agent Profiles 


User Lists E Response Templates 3 Special Objects 


at asu as = aii e 


3. From the secondary navigation bar, select Collectors. 


© Qualys. Cloud Plattorm 


XDR + DASHBOARD THREAT MANAGEMENT ADVANCED ANALYTICS RULES CONFIGURATION 


Data Collection Sources Collectors Appliances 


4. Next, click the New collector button. 


© Qualys. Cloud Platform 


XDR + DASHBOARD THREAT MANAGEMENT ADVANCED ANALYTICS RULES CONFIGURATION 


Data Collection ya Catalog Sources Collectors Appliances 


19 


Total Collectors 
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5. Entera Name and Description for the collector. 


Collector Details 


Name * 


AD_10.114.252.173 


Description * 


This is an Active Directory collector 


987/ 


Type * 


Appliance * 


HeartBeat Interval * 


Collector Details 


Name * 


AD_10.114.252.173 


Description * 


This is an Active Directory collector 


987/ 


Type * 
AD 


7. The Appliance drop-down lists all the active appliances you have already deployed. Select 
the appliance you want to deploy this Active Directory collector on. 

8. After selecting the appliance, define the heartbeat interval for this collector. 
NOTE: Qualys recommends a heartbeat interval of 5m. 
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9. When you set the Type to AD, additional details will open up. You can now choose to 
configure this collector as LDAP or LDAPS. 
A. LDAP 
Follow these steps to configure your collector as LDAP: 
a) Define the Host and Port for this collector. 


Collector Configuration 
@ LDAP LDAPS 
Host * Port * 
BindDN * 
1024, 
Password * 
Refresh frequency in minutes @ * 
Base Context * 
1024, 
Filter * 


b) Next, configure the BindDN and enter the password. 
c) You can then define the refresh frequency in minutes. 
NOTE: Qualys recommends a refresh frequency of 1440 minutes. 
d) Next, add the base context for this collector. 
e) Finally, define the filter you want to set for this collector. 
NOTE: Qualys recommends this filter - (&(objectCategory=person)(objectClass=user)) 


B. LDAPS 
Follow these steps to configure this collector as LDAPS: 
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Collector Configuration 


LDAP e, LDAPS 
Certificate type * 


X.509 


browse 


BindDN * 


1024, 


Refresh frequency in minutes @ * 


Base Context * 


Filter * 


1024 


b) Drag and drop or browse and select your certificate to attach it. 

c) Next, add the base context for this collector. 

d) Youcan then define the refresh frequency in minutes. 

NOTE: Qualys recommends a refresh frequency of 1440 minutes. 

e) Next, configure the BindDN and enter the password. 

f) Now, define the Host and Port for this collector. 

NOTE: The port is typically set as 636. 

g) Finally, define the filter you want to set for this collector. 

NOTE: Qualys recommends this filter - (&(objectCategory=person) (objectClass=user)). 
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10. Finally, click Save to configure your Active Directory collector. 


After a few minutes, when the collector binds successfully, the collector status appears as Active 
under the Collectors tab. 


Catalog Sources Collectors Appliances 


Q 


New collector 


STATUS COLLECTOR NAME TYPE 
Active AD_10.114.252.173 AD 
a minute ago AD_10.114.252.173 


If the status does not show Active, try the following: 
e Recheck the parameters and verify the credentials. 
e Verify the connection between the appliance and the directory host. 


e Ifyou are trying to configure your collector using LDAPS, ensure your Active Directory server 
is set up to allow LDAPS. 


e Attempt configuring the collector on port 389 instead of 636. 
e Ensure you have used FQDN or IP address to reduce name resolution errors. 


After trying these steps, if the status does not change to Active, contact your Qualys Technical 
Account Manager (TAM) or Solution Architect. You can also contact Qualys Support to resolve 
your issue. 
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Windows Agent Preparation 


Qualys Context XDR allows you to leverage existing Qualys Cloud Agents (Windows only) to 
collect event logs from assets on which agents are deployed. You can also deploy fresh agents 
and configure them to collect logs for XDR. 


The Windows Cloud Agents used for Extended Detection and Response (XDR) must be assigned a 
Configuration Profile with XDR enabled. The Windows Cloud Agent must also be activated for 
XDR (see ‘Existing Agent’ below). 


Install New Agent 


For new Windows hosts without an existing Qualys Cloud Agent, refer the Qualys Cloud Agent 
Getting Started Guide for details. 


Existing Agent 


For Windows hosts with an existing Qualys Cloud Agent installed, first enable Extended 
Detection and Response (XDR) within the correct Configuration Profile and then activate the XDR 
license for each Cloud Agent to support XDR. 


Enable XDR via a Configuration Profile 


Before collecting event logs from assets using the Windows Cloud Agent, you first need to enable 
XDR for these agents by either updating an existing configuration profile or by creating a new 
configuration profile. 


Follow these steps to enable XDR through a configuration profile: 


1. Navigate to Cloud Agent module within Qualys Cloud Platform and move to the Agent 
Management tab. 


© QUALYS' 


Dashboard | Agent Management 


Agent Management Agents Activation Keys Configuration Profiles 


Saved Searches + 


2. Next, navigate to the Configuration Profile tab. 


O Qualys 


Cloud Agent v 


Dashboard Agent Management 


EM Agent Management Agents Activation Keys Configuration Profiles 
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3. Choose an existing Configuration Profile (should already be assigned to the hosts) or create a 
new Configuration Profile. 
4. Forthe Configuration Profile selected, click Edit from the Actions menu. 


Cloud Agent v 


Dashboard Agent Management 


& Agent Management Agents Activation Keys Configuration Profiles 


Search 


| New Profile Drag profiles to change the order in which they will be applied 


View 
( z a Profile Name 
| Edit | 
BESS Initial Profile 
Clear selections 
uz testi (Default) 


5. Scroll to the section for XDR and toggle the slider to Enable XDR module for this profile and 


click Save. 
Configuration Profile Edit Turn help tips: On| Of x 
Edit Mode “Extended Detection and Response 
General Info Enable XDR module for this profile (EN) 


Blackout Windows 
Performance 
Assign Hosts 
Agent Scan Merge 
VM Scan Interval 
PC Scan Interval 
FIM 


EDR 


caca 


NOTE: When selecting a configuration profile, ensure the profile is assigned to the correct 
hosts. You can view and modify the hosts assigned to the profile, navigate to the Assign 
Hosts tab from the left pane of the Configuration Profile pop-up. 


All hosts using this configuration profile are now enabled for XDR. 


Qualys Context Extended Detection and Response 22 


Activate Cloud Agents for XDR 


After you have enabled XDR via the configuration profile, ensure that your agents are activated 
for XDR. 


Follow these steps to activate the Windows Cloud Agents for XDR: 
1. Navigate to the Agent Management tab of the Cloud Agent. 


© QUALYS' 


Dashboard | Agent Management 


ELE ET Agents  ActivationKeys iS 


Saved Searches + 


2. On the Agents sub-tab, search for the configuration profile that you enabled XDR on. This 
displays the Agents assigned to this configuration profile. For example, we search for the 
configuration profile named 'DemoProfile’. 


Cloud Agent v 


Dashboard Agent Management 


EE Agents Activation Keys Configuration Profiles 
Saved Searches + 


configurationProfile: DemoProfile 


Y | Activation TS 
Agent Host os Version Last Activity v Last Checked In 
WIN2012R2-98-54 E Windows Micr... 4.40.38 Manifest Downloaded 4 hours ago 
10.115.98 54 4 hours ago 
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3. Select all agents using this configuration profile and click the Actions menu. Next, click the 
Activate for FIM or EDR or PM or XDR option. 


a 


View Asset Details 


Add Tags 

Assign Config Profile 

Activate Agent 

Uninstall Agent | 
Activate for FIM or EDR or PM or XDR | 
Deactivate Agent for FIM or EDR or PM or XDR 


Clear selections 
TU7TTS”"TZA7"2Z06 


4. On the Activate Agents pop-up, toggle the slider to activate the agent for XDR and click 
Activate. 


Activate Agent 


Activate this cloud agent for the modules selected below. 


Ria MOL ACUVALEO. TOU! GYSTILS) are NUL GULIVaLeU 101 PNI. 
92 available of 100 total activations 


Endpoint Detection and Response 
| EDR | 1 agent(s) are currently activated for EDR. 


988 available of 1000 total activations 


Patch Management 
Not activated. Your agent(s) are not activated for Patch. 


10091 available of 10100 total activations 
Supported for only Windows 3.0 and higher Agent version. 


Extended Detection and Response 
1 agent(s) will be activated for XDR. 
186 available of 200 total activations 
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Cloud Agent {v 


5. Finally, after a few minutes, XDR is listed against all the agents you had selected. 


EJ 
Dashboard Agent Management 


P Agent Management 


Agents Activation Keys Configuration Profiles 


Saved Searches + 


Help w Dashboard User w Log out 


y Agents 
Search... @ Search 7 
[Activation Jobs ” v 
O Agent Host os Version Last Activity v~ Last Checked In Configuration Agent Modules Tags 
oO WIN2012R2-98-54 E Windows Micr. 4.40.38 Manifest Downloaded 5 hours ago testi { Cloud Agent 
10.115.98.54 5 hours ago 


What’s Next 


Contact your Solution Architect for details on ‘Day 1- Data Collection’. 
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Appendix A - Appliance Deployment 


Virtual Machine Deployment 


Single-Site 


Internet 


Virtual Appliance 
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Multi-Site 


Internet 


Site 1 


Perimeter Firewall / Proxy Perimeter Firewall / Proxy 


Virtual Appliance Virtual Appliance 
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Appendix B - Windows Cloud Agent Requirements 


| 


Microsoft Windows 10 Pro 
Microsoft Windows 8 

Microsoft Windows Server 2019 
Microsoft Windows 10 Enterprise 
Microsoft Windows Server 2012 R2 [|64 bit 
Microsoft Windows 7 Professional 
Microsoft Windows Vista 
Microsoft Windows 7 Professional 
Microsoft Windows 10 Enterprise [32bit 
Win Vista 2bit 
Microsoft Windows Server 2016 
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